Live data from Hacker News

Who’s behind Wednesday’s epic Twitter hack?

krebsonsecurity.com

111–120 of 536 posts

Re: Who’s behind Wednesday’s epic Twitter hack?

#111
post #61
post #48

It will be interesting to see how the access was gained. I wonder how well this administrative system was protected. Did they have basic controls like: 1) Accessible via corporate VPN only (requiring 2fa) 2) Admin panel protected by 2fa plus necessary authentication+authorization controls 3) Audit trails Short of cooperative access (device handover), I could only see an outsider gaining access to the system due to po…

Many startups and hip companies don't do VPNs anymore - unfortunately they also dont do Zero Trust (which would require machine certs for everything and be enforced) - so stuff is often available over Internet with password auth + maybe MFA. Attacker who gets hold of cookie or bearer token wins. And the best part, support personnel often doesnt have MFA, because its outsourced to countries where smart phones with Aut…

Yes, you're most likely right. While physical tokens are relatively cheap, MFA setup can be not the most straightforward outlay. Still a lot simpler given the many SSO companies out there these days.

That said, tokens are probably simpler than zero trust network setup. Even if you had a zero trust network, you'd still want tokens in case an employee machine is compromised.

Re: Who’s behind Wednesday’s epic Twitter hack?

#112
post #75

Earlier quoted context omitted.

I've been seeing similar scams in Elon's replies, they just copy his profile picture and name and reply with a different account. You might have seen that one

I am used to spotting cryptocurrency scams. The tweet I saw was from his official account, days before the "Wednesday hack".

I don't think that's been reported anywhere, could you link to an archive or something?

Re: Who’s behind Wednesday’s epic Twitter hack?

#113

I think people are still severely under-estimating how dangerous this was. Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value: Archive: http://archive.is/8lCMV https://www.washingtonpost.com/news/worldviews/wp/2013/04/23... This twitter hack could have literally destroyed economies,…

Yes it was dangerous, but nothing is “erased” if that market valuation is restored a few minutes later

Re: Who’s behind Wednesday’s epic Twitter hack?

#114
post #37

> “This is NOT a method, you will be given a full refund if for any reason you aren’t given the email/@, however if it is revered/suspended I will not be held accountable,” Chaewon wrote in their sales thread, which was titled “Pulling email for any Twitter/Taking Requests.” If access were being sold via message board, I wonder if the thread contains stipulations on which accounts are off-limits for being hacked. My…

You don't think that hacking biden and obama will do that too?

They did, the FBI is involved now.

"U.S. FBI is leading an inquiry into the Twitter hack, sources say"

https://www.reuters.com/article/us-twitter-cyber-fbi-exclusi...

Re: Who’s behind Wednesday’s epic Twitter hack?

#115

I think people are still severely under-estimating how dangerous this was. Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value: Archive: http://archive.is/8lCMV https://www.washingtonpost.com/news/worldviews/wp/2013/04/23... This twitter hack could have literally destroyed economies,…

To me, this means that too much trust is placed in social media, rather than we need to police/secure social media more. Social engineering will always be successful to hack into accounts, and hackers are always 1-step ahead of whatever security measures are in place. It is the trust that our society has placed in social media for news/announcements/politics that is the issue.

Re: Who’s behind Wednesday’s epic Twitter hack?

#116
post #107
post #86

Earlier quoted context omitted.

Former presidents are still privy to a lot of information (e.g. they receive national security briefings still). Hacking their technology accounts is absolutely a threat to the security of the US govt, and is one reason the Secret Service specifically monitors their technology usage. I'd bet a lot of money the inclusion of people like Obama and Biden all but guaranteed the FBI/NSA get involved now, or at the very lea…

It's not just about access to information, but actual power and perceived power ; the chances that the average rational person will be fooled and react to "The U.S. Treasury has been ordered to fast-track the evaluation and adoption of Bitcoin as an option for official government transactions" is much higher coming from Trump, Pence, Mnuchin, McConnell, or any number of the official social media accounts of U.S. agen…

I think you're incorrect about the perceived power of a former US president, but regardless I don't think perceived power has any impact on whether the FBI chooses to investigate or not.

That might be a fairy tale some black hats tell themselves, but it seems clear to me that compromising a former president's accounts has serious security implications for the US govt. Obama's access to information (both past and present) is such an overriding concern that his level of perceived power is basically an after-thought.

The FBI often helps out with major breaches of all varieties, let alone ones that involve former heads of state. It's extremely unlikely they're not already involved in this one.

Re: Who’s behind Wednesday’s epic Twitter hack?

#117

This is the most important point: > Also, it seems clear that this Twitter hack could have let the attackers view the direct messages of anyone on Twitter, information that is difficult to put a price on but which nevertheless would be of great interest to a variety of parties, from nation states to corporate spies and blackmailers. My understanding is the hackers used the admin panel to change the email addresses of…

>> Also, it seems clear that this Twitter hack could have let the attackers view the direct messages of anyone on Twitter, information that is difficult to put a price on but which nevertheless would be of great interest to a variety of parties, from nation states to corporate spies and blackmailers. It is not as much money as pundits probably think it is worth. And also, trying to negotiate a blackmail is time consu…

My guess was frantic copy pasta. Since the reset password emails went to both him and the OG twitter user. Plus wouldn’t you need an API key per user and set that all up? I think that takes more time than spamming a tweet.

Re: Who’s behind Wednesday’s epic Twitter hack?

#118

I think people are still severely under-estimating how dangerous this was. Back in 2013 when The Associated Press was hacked with a tweet of "Breaking: Two Explosions in the White House and Barack Obama is injured" and erased $136 billion in equity market value: Archive: http://archive.is/8lCMV https://www.washingtonpost.com/news/worldviews/wp/2013/04/23... This twitter hack could have literally destroyed economies,…

Agreed. This was most likely a "shot across the bow" by a state actor. I have no proof of this. But it's highly public nature would seem to argue against a black-hat commercial interest (e.g. proof of potential to a possible buyer) as it would/will draw too much scrutiny. Also, the crystal clear implication that the damage done could have been far worse, would seem to indicate someone was sending a message. From whom and to whom can only be the subject of speculation, but again, whoever did this must have known that the it would be interpreted as an attack from China to the USA. So either they didn't care because making that obvious was the whole point (ergo, attacker probably China), or the misdirection was the whole point (ergo, attacker probably a power that would stand to benefit from increased tension between USA and China).

Re: Who’s behind Wednesday’s epic Twitter hack?

#119
post #61

Earlier quoted context omitted.

Many startups and hip companies don't do VPNs anymore - unfortunately they also dont do Zero Trust (which would require machine certs for everything and be enforced) - so stuff is often available over Internet with password auth + maybe MFA. Attacker who gets hold of cookie or bearer token wins. And the best part, support personnel often doesnt have MFA, because its outsourced to countries where smart phones with Aut…

To be honest VPN's are a huge pain in the arse for everybody involved.

Yep, I'm actually not saying that VPNs are the right or only (no way) solution I just wanted to highlight that auth is complex and there are often loopholes.

Re: Who’s behind Wednesday’s epic Twitter hack?

#120
post #84

Earlier quoted context omitted.

see this, from earlier: https://news.ycombinator.com/item?id=23860584 "No, you couldn't have made more money than the Twitter hacker" https://fortenf.org/e/security/2020/07/15/twitter-hack.html

I don't buy the stock market argument. People open short positions worth more than $100K every day, especially against companies like Tesla. There would be nothing suspicious about a few such trades. But really, my point is that pulling off a sophisticated exploit involving major celebrities, politicians and CEOs, social engineering/bribery, internal access at a top company etc. doesn't really seem worth the risk if…

> People open short positions worth more than $100K every day

Yes, but you'd need to open one worth $1m to make $100k on a 10% move. $1m is still not "much" in the grand scheme of things, but it's still significant.

Post reply on HN